CVE Vulnerabilities

CVE-2016-9382

Published: Jan 23, 2017 | Modified: Apr 20, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
4.6 MODERATE
AV:N/AC:H/Au:S/C:P/I:P/A:P
RedHat/V3
7.5 MODERATE
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to gain privileges or cause a denial of service (guest OS crash) by leveraging a guest operating system that uses hardware task switching and allows a new task to start in VM86 mode.

Affected Software

NameVendorStart VersionEnd Version
XenXen4.0.0 (including)4.0.0 (including)
XenXen4.0.1 (including)4.0.1 (including)
XenXen4.0.2 (including)4.0.2 (including)
XenXen4.0.3 (including)4.0.3 (including)
XenXen4.0.4 (including)4.0.4 (including)
XenXen4.1.0 (including)4.1.0 (including)
XenXen4.1.1 (including)4.1.1 (including)
XenXen4.1.2 (including)4.1.2 (including)
XenXen4.1.3 (including)4.1.3 (including)
XenXen4.1.4 (including)4.1.4 (including)
XenXen4.1.5 (including)4.1.5 (including)
XenXen4.1.6.1 (including)4.1.6.1 (including)
XenXen4.2.0 (including)4.2.0 (including)
XenXen4.2.1 (including)4.2.1 (including)
XenXen4.2.2 (including)4.2.2 (including)
XenXen4.2.3 (including)4.2.3 (including)
XenXen4.2.4 (including)4.2.4 (including)
XenXen4.2.5 (including)4.2.5 (including)
XenXen4.3.0 (including)4.3.0 (including)
XenXen4.3.1 (including)4.3.1 (including)
XenXen4.3.2 (including)4.3.2 (including)
XenXen4.3.3 (including)4.3.3 (including)
XenXen4.3.4 (including)4.3.4 (including)
XenXen4.4.0 (including)4.4.0 (including)
XenXen4.4.1 (including)4.4.1 (including)
XenXen4.4.2 (including)4.4.2 (including)
XenXen4.4.3 (including)4.4.3 (including)
XenXen4.4.4 (including)4.4.4 (including)
XenXen4.5.0 (including)4.5.0 (including)
XenXen4.5.1 (including)4.5.1 (including)
XenXen4.5.2 (including)4.5.2 (including)
XenXen4.5.3 (including)4.5.3 (including)
XenXen4.5.5 (including)4.5.5 (including)
XenXen4.6.0 (including)4.6.0 (including)
XenXen4.6.1 (including)4.6.1 (including)
XenXen4.6.3 (including)4.6.3 (including)
XenXen4.6.4 (including)4.6.4 (including)
XenXen4.7.0 (including)4.7.0 (including)
XenXen4.7.1 (including)4.7.1 (including)
XenUbuntudevel*
XenUbuntuesm-infra/xenial*
XenUbuntuprecise*
XenUbuntutrusty*
XenUbuntuupstream*
XenUbuntuxenial*
XenUbuntuyakkety*
XenUbuntuzesty*

References